SCA: security update for psitransfer (GHSA-xg8v-m2mh-45m6)

medium Tenable Self-Hosted Container Security Plugin ID 420482

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.2.0, the absence of
restrictions on the endpoint, which allows users to create a path for uploading a file in a file
distribution, allows an attacker to add arbitrary files to the distribution. The vulnerability allows an
attacker to influence those users who come to the file distribution after them and slip the victim files
with a malicious or phishing signature. Version 2.2.0 contains a patch for the issue. CVE-2024-31453
allows users to violate the integrity of a file bucket and upload new files there, while the vulnerability
with the number CVE-2024-31454 allows users to violate the integrity of a single file that is uploaded by
another user by writing data there and not allows you to upload new files to the bucket. Thus,
vulnerabilities are reproduced differently, require different security recommendations and affect
different objects of the application’s business logic. (CVE-2024-31453)

See Also

https://github.com/advisories/GHSA-xg8v-m2mh-45m6

Plugin Details

Severity: Medium

ID: 420482

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.92

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N

CVSS Score Source: CVE-2024-31453

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 4/5/2024

Vulnerability Publication Date: 4/5/2024

Reference Information

CVE: CVE-2024-31453

cwe: CWE-434